1.1.0 - 2026-09-09
Added
- Add canonical
adapters/config,adapters/postgres,
adapters/validation, andadapters/wirepackage paths while retaining the
released integration imports as compatibility facades.
Fixed
- Bound hostile parse and decode diagnostics by
Limits.ErrorBytes, remove
rejected input and unsafe parser causes from returned errors, and preserve
stable Temporal and safe structured classifications.
Changed
- Replace copied repository tooling with the released
go-library-tools
v1.2.0 specification-governance contract while retaining repository-owned
fixtures, API baselines, and content-addressed mutation evidence. - Adopt the checksum-verified
go-library-toolsv1.3.0 CLI, schema-v2 cohesion
metadata, and repository-local cohesion gate while retaining package-owned
source and evidence. - Adopt the checksum-verified
go-library-toolsv1.4.0 CLI and immutable
shared workflow so authority monitoring uses the stabilized request profile
and public-first module resolution. - Pin the shared workflow and CLI to
go-library-toolsv1.6.1 so ordinary CI
runs the proportional local contract while release rehearsals remain
explicit. - Reconcile the
go-calendar,go-config,go-validation, andgo-wire
v1.0.0 checksums with their immutable public module archives. - Require
go-validationv1.1.0 so Temporal findings compose with context
terminal reports without losing either error identity.
Documentation
- Revalidate the pinned Temporal compatibility profile and advance the
loss-checked range authority and supported deployment baseline to PostgreSQL
18.6 without changing the selected mapping behavior.
TEMPORAL-DEC-004 sha256:116d63c5d537d80713f36b10a1a992c6ad104b561abd53f5a3fae3e0ab7f5d1b. - Remove the archived monorepo documentation link; package guidance remains in
the repository-owned documentation. - Link the module to the immutable v1.5.5 Golib ecosystem guidance.
- Publish the auditable temporal specification register
and conformance map: TEMPORAL-DEC-001 sha256:7858a8bedd4143c177fb9670508d564d30049b8c099c66d19ffc3b83a7f3da14,
TEMPORAL-DEC-002 sha256:01b85dcf0eac47ccfa1f69262044dd1206e261a72009a24832f112a2bb8555a1,
TEMPORAL-DEC-003 sha256:2caaf9ce53ec7c2c383c73925f4a672a8f78e4724370bba981fbfdc8c82b2028,
and TEMPORAL-DEC-004 sha256:aa94f39bba10c27ad85d3c2a400ce1190f0695bbba30d0ed526dcd5ec234755c.
Release integrity
- Source commit:
4bd27769eb2359e06a5c8bfbb7f82fb7cd6aef5b - Exact-head CI: https://github.com/faustbrian/go-temporal/actions/runs/34338245379
- Release dry-run: urn:sha256:ba198ea160235a6775a9dde1bbd8c6100042e0ecfeba5ee145702fa29058cbc3
- Assets include a CycloneDX SBOM, SLSA v1 in-toto provenance, and SSH-signed checksums.
Verify the checksum attestation with:
ssh-keygen -Y verify -f ALLOWED_SIGNERS -I brian@cline.sh -n golib-release -s SHA256SUMS.sig < SHA256SUMS